logo_tag
Back

Cyber Attack on Manchester Airports Group Exposes Customer Data at Three UK Airports

Why It MattersAirport-adjacent digital services such as parking, lounge and Wi-Fi bookings are becoming a distinct cyber exposure point separate from core flight operations and payment systems.

What happened

Manchester Airports Group (MAG), which owns Manchester, Stansted and East Midlands airports, said an unauthorised third party gained access to a system holding information tied to car parking, lounge and Fast Track bookings, and Wi-Fi sign-ups. The stolen data includes email addresses, phone numbers, vehicle registrations and postcodes. MAG confirmed that neither it nor the affected system holds customers' bank or payment card details, so financial information was not compromised.

Cyber Attack on Manchester Airports Group Exposes Customer Data at Three UK Airports

Affected customers are being contacted directly and told to be alert to unexpected emails, text messages and phone calls attempting to exploit the stolen information. MAG said it would never unexpectedly contact customers to request payment card details, banking information or passwords. Flights and airport operations have not been disrupted, and MAG said passenger safety and aviation security have not been compromised. Existing bookings remain valid, though the airports' online Manage My Booking service has been temporarily suspended as a precaution, and customers needing urgent booking changes within the next 72 hours have been directed to call customer services.

MAG said it immediately contained the risk on becoming aware of the incident, restricted access to affected systems, engaged specialist cyber security experts, and notified the relevant authorities, with its data protection team overseeing the response.

Industry impact & what to watch

Airports increasingly run ancillary digital services — car parking, lounge access, Fast Track and Wi-Fi sign-up — through systems that sit alongside, but separate from, flight operations and payment processing. This incident shows that a breach can hit that ancillary layer without touching aviation safety systems or financial data, yet still force a precautionary shutdown of customer-facing tools such as an online booking manager.

The response pattern here — containment, restricted system access, external cyber specialists, and notification of authorities — is the standard sequence operators and airports follow once a breach is confirmed, and it determines how quickly normal booking channels can be restored. Because Manage My Booking is suspended, the near-term operational friction falls on customers needing urgent changes, who must now go through telephone customer service instead of self-service.

What happens next depends on how quickly MAG restores full booking system access and on whether contacted customers report follow-on phishing attempts using the stolen contact details. The scope of any regulatory notification response, and whether other airport groups using similar third-party booking or Wi-Fi platforms review their own exposure, are the points worth tracking.

Related Coverage · 1 stories

Airport Cyber Attack Hits Manchester, Stansted and East Midlandsthe-european.eu
Keep Exploring